rdSQL LogordSQL

Privacy Policy

Last updated August 12, 2026

This policy covers rdSQL Desktop (the application) and rdsql.com (the website, account system, and cloud sync service — together, “rdSQL”, “we”, “us”). rdSQL Desktop works fully offline with connections stored only on your device unless you explicitly create an account and enable sync.

What we collect

  • Account data — the email address you register with, and a password hash (PBKDF2-SHA256; we never store your plaintext password) if you use email/password sign-in. If you sign in with Google or GitHub instead, we store the identity the provider gives us (their user ID and the email/name/avatar they share) — we never see your Google or GitHub password.
  • Device metadata — a name, platform, and last-seen timestamp for each device you sign in from, so you can see and revoke devices from your account page.
  • Encrypted sync data — if you opt in to cloud sync, your connection metadata (name, host, port, engine — not secrets) syncs as plain data, but passwords/SSH keys/other credentials are encrypted on your device before they ever leave it. The encryption key is derived and held client-side; our servers only ever see ciphertext they cannot decrypt.
  • Billing data — if you upgrade to Pro, payment is handled entirely by Stripe. We receive your subscription status and a Stripe customer/subscription ID, never your card number.
  • Anonymous usage analytics — off by default. If you opt in from the app, we record aggregate, anonymous counters (e.g. “a Postgres connection was created”) against a fixed allowlist of event names — never a per-event log, never anything that could identify you.

What we don’t collect

Query results, table contents, and database credentials you haven’t opted to sync never leave your device. rdSQL Desktop has no telemetry beyond the opt-in analytics above.

How we use it

To operate your account (authentication, device management, sync), process billing through Stripe, send transactional email (password resets — nothing else), and, in aggregate/anonymous form, to understand which database engines and features are actually used so we know where to invest development time.

Third parties

  • Cloudflare — hosts the website, backend, and database (Workers, D1, R2).
  • Stripe — processes all payments; see Stripe’s privacy policy.
  • Google / GitHub — only if you choose to sign in with one of them.
  • Advertising — this site may show ads served by Google, including via Google AdSense. Google may use cookies to serve ads based on your prior visits to this or other websites. You can opt out of personalized advertising by visiting Google Ads Settings, and third-party vendors may also use cookies under Google’s policies — see How Google uses information from sites that use its services.

Cookies & local storage

The website itself doesn’t use tracking cookies for its own functionality — your session token is kept in your browser’s local storage, not a cookie. If advertising is enabled on this site (see above), Google and its partners may set their own cookies for that purpose.

Your rights

You can rename or revoke any device, and sign out, directly from your account page. To delete your account and associated data, or to request a copy of what we hold about you, contact us at privacy@rdsql.com.

Children’s privacy

rdSQL is a developer tool not directed at children, and we don’t knowingly collect data from anyone under 13.

Changes

We’ll update the date at the top of this page when this policy changes. Material changes will be noted in the app’s changelog.

Contact

Questions about this policy: privacy@rdsql.com.